Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5. | |
| Title | GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction | |
| Weaknesses | CWE-352 CWE-434 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T19:54:11.631Z
Reserved: 2026-06-22T16:39:01.043Z
Link: CVE-2026-56660
Updated: 2026-10-01T19:53:35.242Z
Status : Deferred
Published: 2026-10-01T20:17:26.643
Modified: 2026-10-01T20:23:46.493
Link: CVE-2026-56660
No data.
OpenCVE Enrichment
Updated: 2026-10-01T20:30:04Z